Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4rqj-h9m9-94p6

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw exists within JSON RPC Request handling. By setting the checksession parameter to a specific value, it is possible to bypass authentication to critical functions. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4752.

This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw exists within JSON RPC Request handling. By setting the checksession parameter to a specific value, it is possible to bypass authentication to critical functions. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4752.

EPSS

Процентиль: 97%
0.43582
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 8 лет назад

This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specific flaw exists within JSON RPC Request handling. By setting the checksession parameter to a specific value, it is possible to bypass authentication to critical functions. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-4752.

CVSS3: 9.8
fstec
около 8 лет назад

Уязвимость программного обеспечения для архивирования и восстановления данных NetVault Backup, связанная с недостаточным контролем доступа, позволяющая нарушителю обойти процедуру аутентификации и повысить привилегии до системных

EPSS

Процентиль: 97%
0.43582
Средний

9.8 Critical

CVSS3